A threat actor team claims to have gained unauthorized access to an editorial management platform associated with SAGE Publishing, exposing information tied to more than 120,000 users and threatening to distribute credentials that could provide others with access to the system.
The claim was posted Sept. 6 and includes a screenshot that appears to show an authenticated SAGE Edit administrative interface. The visible dashboard displays author accounts associated with different journals, along with names, email addresses, roles, journal codes and article identifiers.
More significantly, the actors claim the compromised account provides access beyond the user directory, including journal management information and editorial email correspondence.
SAGE had not issued any public statement confirming the claimed unauthorized access at time of publication. SAGE’s public service status page also showed its monitored publishing services as operational with no incident reported for Sept. 6.
Screenshot appears to show SAGE Edit access
The evidence published with the claim shows what appears to be the user management area of SAGE Edit. The interface includes Publisher, Journal and User sections and displays pagination extending to more than 8,000 pages of user records.
SAGE publicly identifies SAGE Edit as an editing portal used during its production workflow. Corresponding authors can receive and review article proofs through the platform before publication.
The threat actors claim approximately 120,000 user records are accessible and say the exposed information includes email addresses, full names, user roles, journal and article identifiers, profile information and associations between authors and publications.
BreachNews has not independently verified the claimed 120,000-user count or determined whether the actors extracted the underlying database.
Editorial correspondence allegedly accessible
The claim extends beyond basic account information. According to the actors, their access includes email records containing recipients, CC and BCC recipients, subjects, message content and timestamps.
They also claim access to proofing-related communications, internal staff email addresses, publisher information, journal management records and mappings associated with editors and publishing personnel.
If those claims are accurate, the incident could expose communications between authors, editors and publishing staff in addition to personal information contained in user profiles.
The available evidence does not establish whether passwords are accessible, whether unpublished manuscripts can be viewed or modified, or how broadly the compromised account can make changes across SAGE’s publishing environment.
Actors threaten to distribute account access
The actors are not merely claiming to possess an extracted database. Their post says they intend to distribute credentials for the compromised account to other members of the cybercrime community.
If the credentials remain valid, distributing them could expand the incident by allowing additional unauthorized parties to browse whatever information and functionality is available to the compromised account. BreachNews has not attempted to use the credentials and cannot establish whether they remain functional.
BreachNews is not publishing the credentials, underground forum location, individual account information or other details that could facilitate unauthorized access.
Same team recently claimed Pattons database
The SAGE claim follows another recent alleged compromise attributed to the same threat actor team. BreachNews previously reported that the group allegedly leaked a Pattons shipping database containing customer and shipment data associated with the company’s use of myTNT.
In that incident, the actors claimed the database contained names, email addresses, phone numbers, postal addresses, shipment and booking numbers, tracking information, invoice data, customs information and other logistics records. Evidence accompanying the claim appeared to show records containing shipping and contact information.
The latest SAGE post suggests the team is continuing to target business applications and databases containing large volumes of user and operational information. BreachNews has not established how the actors obtained access to either environment, and there is currently no evidence that the Pattons and SAGE incidents share the same initial access method.
The screenshot accompanying the SAGE claim provides evidence consistent with access to a SAGE-branded editorial system, but it does not independently establish the full scope described by the actors. Until SAGE confirms the incident or additional evidence becomes available, the reported 120,000-user exposure remains alleged.












